remote

Salary
$185,000–$260,000
Posted
Jul 7, 2026
Location
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A senior individual-contributor engineering role focused on owning the architecture and development of identity and access management infrastructure across a cybersecurity simulation platform. Day-to-day work centers on building and extending Keycloak-based identity services, designing a Relationship-Based Access Control authorization layer using Topaz/OPA, and creating adjacent services such as directory and user management. The role also involves setting cross-team authentication and authorization standards and mentoring senior engineers.

Staff level · Remote · Full-time

Pay in the description: $185,000–$260,000

Must have (8)
KeycloakOAuth 2.0OIDCSAMLOPATopazKubernetesCI/CD
Nice to have (2)
on-premises infrastructureFedRAMP or SOC 2

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 1,650 people nationally plausibly meet what this posting asks for (software developers). range 340–2,450

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What gives you an edge
Keycloak4%SAML6%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
CI/CD45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $138,970 (middle half $107,524–$175,762). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (6)

Keycloak is listed as 'a plus' in the 'Who you are' section, but the JD simultaneously states that 'willingness to develop deep expertise in Keycloak' is 'essential' and the role's primary deliverable is 'Keycloak-based identity infrastructure.' Given that Keycloak is the named IdP the role is explicitly hired to own and build, it is treated as a hard gate despite the softening qualifier on prior experience.

Topaz/OPA: Topaz is the current implementation vehicle for the ReBAC authorization layer; the JD states 'An understanding of ReBAC and how it differs from RBAC and ABAC models is essential' and lists Topaz/OPA as the implementation. Both are marked required as the role is explicitly hired to design and build this layer.

On-premises / self-hosted infrastructure comfort is described as 'a strong plus,' so it is marked preferred.

Experience in security-sensitive or compliance-driven environments (DoD, FedRAMP, SOC 2, or similar) is described as 'a strong plus' — marked preferred. FedRAMP and SOC 2 are listed as named alternatives within that single requirement.

No minimum total years of experience is stated numerically in the JD; the role is framed at the Staff level by title and scope.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗